Tag: Zero Day
-
A Word on Microsoft and Vulnerability Exploitation

Intro Microsoft Security Response Center (MSRC) is the group responsible for triage when researchers report new vulnerabilities. They handle a wide variety of other tasks, but my focus is on their analysis of vulnerabilities in one context or another. That could be the researcher’s disclosure or investigating an actively exploited vulnerability in a customer environment.…
-
Almost Zero Value in “Zero Progress on Zero-Days”; a Rebuttal

The following blog is general comments and a rebuttal of sorts to the following paper: “Zero Progress on Zero-Days: How the Last Ten Years Created the Modern Spyware Market” by Mailyn Fidler, Assistant Professor, University of New Hampshire, Franklin Pierce School of Law [Link] Unfortunately, I can’t easily cut and paste from this PDF which…
-
Two Definitions of Zero Day Apparently

What is a “zero day vulnerability”? It’s a term that is frequently used in the vulnerability disclosure ecosystem. I have blogged on this topic frequently and reading some of this will give more history and context, so I won’t rehash everything. If you read one blog, make it “No One Will Burn A Zero Day…
-
No one will burn a zero day on you…?

For at least two decades, a common mantra in the Information Security industry is that “no one will burn a zero day on you!” This is typically said to a person, often someone that comes across as overly paranoid, or perhaps a small hobby website. This term refers to zero day vulnerabilities, ones that are…
-
Let’s Talk About 0-days

[This was a first draft of an article to be published on the Flashpoint Threat Intel blog. Ultimately, parts of it were adopted for a different blog but the original remains considerably different. Curtis Kang contributed significantly to the finished blog below.] Zero-days (0-days and other variations) are exploitable vulnerabilities that the general public is…
-
Rebuttal: Skeletons in the Closet

On April 22, 2022, Nate Warfield of Prevailion published an article on Threatpost on the topic of zero days. I’m a little late to this article, but because this horse still has some life in it apparently, I feel obligated to once again point out how the term ‘zero day’ has basically lost all meaning.…
-
Perlroth & The First (Zero-Day) Broker
I am currently reading “This Is How They Tell Me The World Ends” by Nicole Perlroth, only on page 60 in Chapter 5, so a long ways to go before completing the 471 page tome. I hit chapter 4, titled “The First Broker” and it was of specific interest to me for sure, prompting this…
-
Detecting the Recent Adobe 0-Day (APSA10-01) with Nessus

[This was originally published on the Tenable blog.] On June 4, 2010, Adobe announced a new attack being exploited in the wild that targeted Adobe products, and word spread quickly. Adobe’s security bulletin (APSA10-01) provided few details, but confirmed that attackers were actively exploiting a vulnerability that affected their Flash Player, Adobe Reader and Acrobat.…
-
Getting ‘lucky’: When Nessus Finds 0-Days

[This was originally published on the Tenable blog.] Historically, vulnerability scanners have been signature based: looking for issues based on a static signature, behavior such as bannerhttps://pt-br.tenable.com/blog/getting-lucky-when-nessus-finds-0-days output or service response output to certain queries. If the scanner was not specifically directed to look for a given vulnerability, it would not find it. Many in…